WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent < 2.14.2 - Cross-Site Request Forgery

2022-02-07 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 2.14.2
Affected Version< 2.14.2
CVSS6.5Medium
CVECVE-2022-0445
View all Real Cookie Banner: GDPR & ePrivacy Cookie Consent vulnerabilities

Vulnerability Overview

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack.

Technical Analysis

REMEDIATION: Update to version 2.14.2, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C